
IRAP vs ISO 27001 for Australian SaaS Companies
You have built something a government agency wants to buy. Somewhere in the procurement pack the words IRAP and ISO 27001 appear, sometimes in the same sentence, and it is not obvious whether you need one, the other, or both.
They are not two versions of the same thing. One is an international certification of how you manage security. The other is an Australian assessment of a specific system against a specific control set, and it does not result in a certificate at all. Confusing them is an expensive mistake for a small SaaS company, so this guide sets out what each one is, who asks for it, and the order to do them in.
What ISO 27001 is
ISO/IEC 27001 is an international standard for an information security management system. You build the management system, an accredited certification body audits it, and if you pass you receive a certificate stating what the certification covers. Certification runs on a three year cycle with surveillance audits along the way.
What it certifies is the way you manage security: how you assess risk, choose controls, assign responsibility, train people and improve over time. It is recognised worldwide, which is why enterprise and overseas buyers ask for it. For most Australian SaaS companies it is the first serious credential worth holding.
What an IRAP assessment is
IRAP is the Infosec Registered Assessors Program, administered by the Australian Signals Directorate. An IRAP assessor is an ASD endorsed professional who assesses a system against the controls in the Australian Government Information Security Manual, the ISM, and reports on how effectively those controls have been implemented.
Here is the part that surprises most founders. IRAP assessors do not certify, accredit or endorse systems on behalf of ASD. The assessment produces a security assessment report describing the system, the controls, the residual risks and the recommended remediation. The decision about whether that risk is acceptable is made by the government entity itself, through its authorising officer, as part of authorising the system for use.
So there is no such thing as being “IRAP certified”. A system can be IRAP assessed, and an agency can then authorise it. Vendors who advertise IRAP certification are describing something that does not exist, and government buyers notice.

Which one does your buyer actually want
Enterprise and overseas buyers
ISO 27001, or a SOC 2 report, almost every time. An IRAP assessment will mean very little to a procurement team in Sydney buying business software, and nothing at all to one in London. If your pipeline is commercial, this is where your money goes. Working out which of the two suits you is a separate question we cover in our comparison of SOC 2 and ISO 27001.
Australian government buyers
This is where IRAP appears, and usually only when the system will handle government information carrying a sensitivity marking or security classification such as OFFICIAL: Sensitive or PROTECTED. If an agency will hold nothing sensitive in your product, they may be satisfied with ISO 27001, your Essential Eight alignment and a recent penetration test.
Ask the question directly before you spend anything: what marking or classification of information will be held in the system, and what assurance does the agency require before it can be authorised? Get the answer in writing. A great deal of money has been spent on assessments that nobody asked for.
Defence suppliers
If you are selling into Defence, the requirement may be DISP membership rather than IRAP, and the two are frequently confused. Our guide to DISP membership covers what that pathway involves.
The order that saves money
For a SaaS company of 20 to 100 people, doing ISO 27001 first and IRAP second is usually the cheaper path, because the ISMS produces most of the documentation an IRAP assessment expects to see.

Confirm the requirement is real
One agency contact saying “you will probably need IRAP” is not a requirement. A written statement of the classification involved and the assurance expected is. This step costs nothing and regularly saves a great deal of money.
Build the management system
Risk assessment, policies, access control, logging, incident response, supplier management, staff training. This is ISO 27001 work, and it is also the evidence an ISM assessment will ask you to produce. Getting your ISO 27001 project right at this stage keeps both efforts contained.
Gap assessment against the ISM
The ISM is more prescriptive than ISO 27001. It specifies technical requirements in areas such as cryptography, system hardening, logging and gateway configuration, and it is updated regularly by ASD. A readiness assessment against the ISM controls that apply to your system tells you what the real work is before an assessor is engaged.
Expect this to surface engineering work rather than paperwork: cipher suites, logging retention, privileged access, patching cadence and how your environment is segregated.
Remediate and document
Close the gaps, then produce the documentation an assessment relies on, including a system security plan describing your system and how each applicable control is implemented. For most companies this is the longest phase.
Engage the assessor
The assessor examines the system, tests evidence, and reports findings and residual risks. That report goes to the agency, and the agency decides. Plan for the possibility that the report identifies items you need to fix before authorisation.
What this costs a small company
We do not publish prices here, because the range is genuinely wide and depends on the size of the system and the classification involved. What is worth knowing is the shape of the spend. The assessment itself is usually the smaller line item. The engineering work to meet ISM requirements, and the internal time to produce documentation, is where the budget goes.
If you want a sense of the components, our guide to ISO 27001 certification cost in Australia covers the pieces that make up a realistic budget, and the same logic applies here. Budget for the remediation you cannot yet see, and treat any quote that arrives before someone has looked at your architecture with caution.
Reusing your ISO 27001 evidence
A good deal of what you produce for ISO 27001 carries straight across: your risk assessment, your asset and supplier registers, access control records, incident response plan, training records and change management evidence. What does not carry across is the technical detail. An ISM assessment asks how a specific control is configured on a specific system, so expect to produce configuration evidence, architecture detail and logging samples that your certification audit never needed.
Plan for that difference. Teams that assume their certificate covers the assessment tend to lose a month rebuilding evidence at the worst possible moment.
Where the Essential Eight fits
Government buyers frequently ask about the Essential Eight as well. It is a set of eight mitigation strategies from ASD with defined maturity levels, and it is narrower than either ISO 27001 or the full ISM. For a startup, reaching a defined Essential Eight maturity level is a fast, credible signal to Australian buyers and a sensible thing to do early, whether or not IRAP is ever on your roadmap.
Common questions
Can we say we are IRAP certified?
No. IRAP assessors do not certify or accredit systems on behalf of ASD. The accurate wording is that your system has been assessed by a registered IRAP assessor against the ISM at a stated classification, and that agencies may use that report to inform their own authorisation decision.
Does ISO 27001 cover the ISM requirements?
Partly, and not automatically. ISO 27001 tells you to select controls based on risk. The ISM specifies particular technical controls. An ISO 27001 certified company will have the governance and documentation in place, and will usually still have technical gaps against the ISM to close.
How long does the whole path take?
For a small SaaS company starting from a reasonable baseline, ISO 27001 commonly takes six to twelve months, and an IRAP readiness and assessment cycle adds several months on top of that. Start the conversation with the agency early, because their authorisation process has its own timeline.
Do we need an IRAP assessment to sell anything to government?
No. Plenty of Australian software is sold to government without one. It becomes relevant when the system holds government information at a classification that requires that level of assurance. Ask, do not assume.
Working out your path
The right answer depends on who is actually buying. If your pipeline is commercial with one interested agency, get ISO 27001 done and revisit IRAP when the agency requirement is confirmed in writing. If government is your entire market, plan the ISM work in from the start and treat ISO 27001 as the foundation rather than a detour.
Siege Cyber helps Australian SaaS companies work out which credential their buyers need and get there without spending on the wrong one. Have a look at our IRAP readiness services and ISO 27001 services, or get in touch for a straight answer about your situation.